<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513102#M2722</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222081"&gt;@maksymilianjan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks! Can you please share the query to create this alert?&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2022 09:52:02 GMT</pubDate>
    <dc:creator>RahulPrajapati</dc:creator>
    <dc:date>2022-08-26T09:52:02Z</dc:date>
    <item>
      <title>Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513093#M2716</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does Cortex XDR run the malware scan on the USB device immediately when it is inserted into the endpoint?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 08:27:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513093#M2716</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2022-08-26T08:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513094#M2717</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Currently XDR doesn't have a feature to &lt;SPAN&gt;run the malware scan on the media / USB devices immediately when inserted into the endpoint.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;You may check with your support account team to see if there are any possibilities of getting it in future versions as part of product developments.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 09:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513094#M2717</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-08-26T09:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513096#M2719</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the response!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way by which we can know from the XDR console; when the user is inserting the USB devices on their endpoints?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 09:14:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513096#M2719</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2022-08-26T09:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513099#M2720</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Using device control you can manage devices connecting to endpoint. Refer link below for more details.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control&lt;BR /&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After you apply Device Control rules in your environment, use the&amp;nbsp;&lt;SPAN&gt;Endpoints -&amp;gt;&amp;nbsp;&lt;SPAN&gt;Device Control Violations&amp;nbsp;&lt;SPAN&gt;page to monitor all instances where end users attempted to connect restricted USB-connected devices and&amp;nbsp;&lt;VAR class=""&gt;Cortex&amp;nbsp;&lt;VAR class="" data-product="xdr"&gt;XDR&amp;nbsp;&lt;SPAN&gt;blocked them on the endpoint. &lt;/SPAN&gt;&lt;/VAR&gt;&lt;/VAR&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;All violation logs are displayed on the page. You can sort the results, and use the filters menu to narrow down the results. For each violation event&amp;nbsp;Cortex&amp;nbsp;XDR&amp;nbsp;&lt;LI-WRAPPER&gt;logs the event details, the platform, and the device details that are available.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Please mark this solution if it answered your queries on this post.&lt;BR /&gt;Thank you!&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 09:37:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513099#M2720</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-08-26T09:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513100#M2721</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to add some tips into this, there is a way to create querys/alerts even on this kind of events.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For example check the following link:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.sciencedirect.com/topics/computer-science/window-registry#:~:text=Windows%20registry%20stores%20information%20about,been%20plugged%20into%20the%20system" target="_blank"&gt;https://www.sciencedirect.com/topics/computer-science/window-registry#:~:text=Windows%20registry%20stores%20information%20about,been%20plugged%20into%20the%20system&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;I have used similar techniques to this in investigations but its rather on your side and more of a "windows internals" thing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 09:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513100#M2721</guid>
      <dc:creator>maksymilianjan</dc:creator>
      <dc:date>2022-08-26T09:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513102#M2722</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222081"&gt;@maksymilianjan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks! Can you please share the query to create this alert?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 09:52:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513102#M2722</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2022-08-26T09:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513151#M2726</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222081"&gt;@maksymilianjan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we know that Cortex XDR is an execution based detection and prevention solution, it has the capability to detect malwares if they execute even from removable media on the endpoint. As a result on connection scan is something that is not a hard requirement for detection of malwares. Practice recommendation in these used cases can be that you use restriction profiles to restrict execution of executables and other files from the removable media and if the user intends to execute some files present on the media, it should be copied to a folder on the endpoint locally for execution. Assuming, that the user does not execute the file instantaneously and if it stays on the system, periodic scan should be able to determine the verdict for the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, the Cortex XDR agent does not perform USB scan on connection, however, it has the capability to scan removable media as part of the periodic malware scan if required. You can enable this in the malware profiles, under category&amp;nbsp;&lt;STRONG&gt;Endpoint Scanning&lt;/STRONG&gt;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Periodic Scan -&amp;gt; Enabled&lt;/STRONG&gt; and under then you should have the option to&amp;nbsp;&lt;STRONG&gt;Scan Removable Media Drives-&amp;gt;Enabled.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshot below for reference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 18:11:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/513151#M2726</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-26T18:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/548799#M4730</link>
      <description>&lt;P&gt;Do you happen to know if the "Scan Removable Drives" would include mapped network drives? We have hundreds of endpoints, and the last thing we need is all of them scanning the same shared network drive.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 17:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/548799#M4730</guid>
      <dc:creator>EdwardDiaz</dc:creator>
      <dc:date>2023-07-10T17:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/548861#M4734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208745"&gt;@EdwardDiaz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mapped network drives are not scanned as part of the malware scan by the endpoints. Instead, if initiated on the endpoint which hosts the network drive, the network drive being considered a part of a persistent drive for a specific endpoint/server, will be scanned as a drive path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 06:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/548861#M4734</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-11T06:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR run the Malware scan if the USB device is inserted into the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/549174#M4755</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To add on&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192854"&gt;@creddy&lt;/a&gt;&amp;nbsp;'s response, you can choose to create XQL queries for looking into file write events on removable media using XQL queries which essentially would give the same result. If you have identity analytics module active. Uncommon USB connection activities are anyways automatically tracked and generate alerts for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 04:52:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-run-the-malware-scan-if-the-usb-device-is/m-p/549174#M4755</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-13T04:52:19Z</dc:date>
    </item>
  </channel>
</rss>

